What to look out for today
1) VPN / remote access gateways under pressure: Reports of SonicWall SMA appliances being exploited as zero-days before public disclosure highlights ongoing risk to internet-facing remote access devices.
2) “ClickFix” / fake CAPTCHA verification: A campaign used CAPTCHA-style prompts to trick people into infecting their own machines with malware. The technique is simple and can be repurposed beyond the original targets.
3) Supplier/update-channel abuse: A separate report describes attackers abusing a product update mechanism to reach victims. This is a reminder to treat software updates and management tools as high-trust pathways.
Why this matters to smaller businesses
- Business disruption: If a VPN/remote access box is compromised, attackers may gain a foothold that leads to account takeover, data access, ransomware, or prolonged IT downtime.
- SMEs are exposed by default: Many smaller organisations rely on a single edge device (VPN) and outsourced IT. If that device is reachable from the internet, it’s a high-value target.
- Staff are the delivery route: Fake “verification” or CAPTCHA steps can bypass technical controls by persuading users to do the risky action themselves.
- Supply chain risk is real: If an update channel or management tool is abused, even well-run organisations can be impacted quickly.
Warning signs
- Staff report being asked to complete a “CAPTCHA” that involves extra steps beyond ticking a box (e.g., instructions to copy/paste something, run a command, install a plugin, or “verify you’re human” by enabling settings).
- Unexpected remote access behaviour: new VPN user accounts, logins at odd hours, or login attempts from unusual locations.
- Unplanned VPN outages, slowdowns, or repeated reboots of remote access devices.
- Unexpected prompts to approve sign-ins, MFA fatigue requests, or “security verification” emails/messages related to remote access.
- Unusual update prompts for networking/security tools or requests to “manually apply” an update from an emailed link.
How attackers may exploit the situation
- Edge-device compromise: Attackers target internet-facing VPN/remote access appliances to gain deep access without needing a phish first.
- Social engineering with “ClickFix”: Victims are tricked into running steps that install malware, often framed as fixing an error or completing verification.
- Abusing trusted tooling: Where update mechanisms or management pathways are misused, attackers can distribute malicious changes while appearing legitimate.
What to do today
- Send a 2-minute staff note: “CAPTCHAs never require you to run commands, install software, or paste text. If a verification prompt asks for anything beyond a checkbox/image selection, stop and report it.”
- Confirm remote access ownership: Identify who manages your VPN/remote access device(s) and ensure you can reach them quickly (including out-of-hours contact if you rely on remote work).
- Review access basics: Ensure MFA is enforced for remote access and admin portals, and remove old accounts that no longer need VPN access.
- Log and alert: Make sure VPN login events are being monitored (even if it’s just daily review) and that you’ll know quickly if configuration changes occur.
- Prepare for disruption: Check you have an offline way to reach staff/customers if email or VPN is down (phone list, alternate comms channel).
Ask your IT provider
- Do we have any SonicWall SMA devices (or other internet-facing VPN gateways)? Who is responsible for monitoring and emergency response?
- How quickly do you assess and act on reports of in-the-wild exploitation against remote access appliances?
- What logs do we retain for VPN access and admin changes, and for how long?
- Do we have a tested plan to revoke VPN sessions, rotate credentials, and confirm no persistence if we suspect compromise?
- How do you validate software/firmware updates for networking and security tools (and prevent “manual update from an email link” scenarios)?
Patch watch - only one short paragraph, and only if relevant
If you use SonicWall SMA or similar remote access appliances, treat vendor security updates and provider guidance as time-sensitive. The key SME action is not researching technical details, but confirming ownership, monitoring, and a rapid “is this exposed and are we protected?” check with your IT provider.
One action today
Send a short staff alert: CAPTCHAs/“verification” pages should never ask you to run commands, paste text, or install anything—stop and report immediately.
Related Actions On Cyber resource
CTA: Use the Actions On Cyber “Suspicious email & fake verification (CAPTCHA/2FA) triage checklist” for staff and front-desk teams.
Sources
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access (The Hacker News)
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware (The Hacker News)
- Hackers abuse ViPNet software to target Russian govt agencies (BleepingComputer)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.